Top Consultants for NCSC Cyber Essentials Compliance for UK SaaS Companies: Win Big
Alexander Sverdlov
Security Analyst

If you run a UK SaaS company and you have been asked for Cyber Essentials by a prospect, a public-sector buyer, or an enterprise procurement team, you are probably weighing whether to self-assess, hire a consultant, or ignore it and hope the requirement goes away. It will not go away. Cyber Essentials has quietly become a baseline expectation across UK government supply chains and a growing number of private contracts. This article explains what the scheme actually requires, when bringing in a consultant is worth it, and how to choose one without wasting money.
I have spent more than a decade running security assessments for companies of every size, and I will be direct: Cyber Essentials is a genuinely useful baseline, but it is also frequently misunderstood. It is not a security strategy, it is a floor. Treat it as the start of a maturity path and it pays back. Treat it as a badge to buy and forget, and you will fail your first serious security question from a real enterprise buyer.
What Cyber Essentials Is
Cyber Essentials is a UK government-backed certification scheme, owned by the National Cyber Security Centre (NCSC) and delivered by IASME as the accreditation body through a network of certification bodies. It defines a set of baseline technical controls designed to protect against the most common internet-based attacks - the commodity threats that make up the bulk of what any exposed organisation actually faces.
There are two levels:
- Cyber Essentials. A self-assessment questionnaire verified by a certification body. You answer against the technical control themes and attest to your configuration. Certification lasts twelve months.
- Cyber Essentials Plus. The same control set, but independently tested and verified by a qualified assessor through hands-on technical audit, including vulnerability scanning of a sample of your systems. It carries far more weight with serious buyers because it is verified, not merely declared.
The scheme is built around five technical control themes. Every requirement maps back to one of these:
- Firewalls. Boundary and host firewalls configured to control inbound and outbound traffic, with default credentials changed and unnecessary services closed.
- Secure configuration. Systems hardened, default passwords removed, unnecessary software and accounts disabled.
- Security update management. Operating systems and applications kept in support and patched promptly, with critical and high-severity fixes applied within the scheme's defined window.
- User access control. Least-privilege accounts, unique credentials, controlled administrative access, and multi-factor authentication where required, particularly for cloud services.
- Malware protection. Anti-malware, application allow-listing, or equivalent controls on in-scope devices.
The requirements are published in a document called Cyber Essentials: Requirements for IT Infrastructure. The current technical requirement set is periodically updated, so always work against the version in force for your certification cycle rather than an older copy.
Why It Matters for SaaS Companies Specifically
For a SaaS business, Cyber Essentials tends to matter for two reasons. First, it is a common gate in UK public-sector procurement. Government contracts that involve handling certain information or personal data frequently require Cyber Essentials as a minimum, and it is a recurring line item in supplier due diligence. Second, enterprise buyers increasingly use it as a quick filter. It will not win a large enterprise deal on its own, but its absence can quietly remove you from a shortlist before you ever get a conversation.
The wrinkle for SaaS is scope. Cyber Essentials assesses the devices and services in scope for your organisation - end-user devices, servers, and cloud services that your organisation administers. Cloud services are firmly in scope in current versions of the scheme, including the platforms your team uses to run the business. That surprises founders who assumed their production environment on a major cloud provider was somehow out of scope. It is not, and getting scope right is where consultants earn their fee.
When to Hire a Consultant Versus Self-Assess
Plenty of small companies self-certify successfully, and there is nothing wrong with that. Be honest about which situation you are in.
Self-assessment is usually fine when: your estate is small and homogeneous, you already enforce MFA and patching, your team understands your cloud configuration, and you mainly need the basic certificate to satisfy a specific requirement.
A consultant is worth it when: you have a mixed or fast-growing estate, you are unsure how to scope cloud and remote-working devices, you are going for Cyber Essentials Plus and want to pass the hands-on audit the first time, or you want the certification to be the first step of a broader security programme rather than an isolated exercise. The failure I see most often in Plus assessments is a device or cloud service that was left out of scope incorrectly, or patching that is inconsistent across the estate. Both are cheap to fix before an assessment and expensive to discover during one.
What a Good Cyber Essentials Consultant Actually Does
Anyone can hand you a questionnaire. The value of a good consultant is in the work around it. Here is what to expect from an engagement worth paying for:
- Scope definition. Getting the boundary right the first time, including cloud services, remote and BYOD devices, and any segmentation that legitimately narrows scope.
- Gap assessment. Mapping your current state against the five control themes and producing a concrete remediation list, not a vague score.
- Remediation support. Practical help closing gaps - enforcing MFA, tightening firewall and cloud configuration, standardising patching, and removing unsupported software.
- Evidence and readiness. Preparing you so that a Cyber Essentials Plus assessor finds what they expect to find. This is where a rehearsal against the audit steps prevents a fail.
- A path beyond the badge. A good adviser positions Cyber Essentials as the foundation for whatever comes next, whether that is ISO 27001, SOC 2, or a broader security roadmap.
Cyber Essentials Versus Cyber Essentials Plus
| Aspect | Cyber Essentials | Cyber Essentials Plus |
|---|---|---|
| Verification | Self-assessment, verified by a certification body | Independent hands-on technical audit |
| Vulnerability scanning | Not performed | Sample of systems scanned by assessor |
| Buyer confidence | Basic assurance | Significantly stronger, evidence-based |
| Effort to achieve | Lower | Higher, requires the controls to genuinely work |
| Typical use | Entry requirement, first certification | Contracts and buyers demanding verified assurance |
| Validity | Twelve months | Twelve months |
A sensible route for most SaaS companies is to achieve Cyber Essentials first, use the remediation period to make the controls real, and then progress to Plus when a buyer requires it or when you want the stronger assurance for competitive reasons.
How to Choose a Consultant Without Wasting Money
The market is crowded and quality varies. A few filters cut through it quickly:
- Check accreditation. Certification is delivered through IASME-accredited certification bodies. If you are going for Plus, confirm who will actually perform the assessment and that they are qualified to do so.
- Look for SaaS and cloud experience. Scoping cloud-native environments is where inexperienced advisers get it wrong. Ask how they handle cloud services and remote devices in scope.
- Insist on a real gap assessment. A credible consultant tells you what is broken and how to fix it, not just whether you passed a form.
- Beware badge-only offers. If the pitch is purely about getting a certificate fast with no remediation, you are buying a decoration, not security.
- Ask about the path beyond. A good adviser will connect Cyber Essentials to your longer-term compliance and security goals rather than treating it as the finish line.
Where Cyber Essentials Fits in a Bigger Picture
Cyber Essentials proves you have the basics right. It does not prove you have a security programme. If your buyers are enterprise or regulated, you will eventually be asked for more - typically a recognised framework like ISO 27001 or, for US-facing SaaS, SOC 2. The good news is that the discipline Cyber Essentials builds around asset scope, configuration, patching, and access control is the same foundation those larger frameworks rest on.
This is exactly why I advise treating certification as step one. A firm that scrambles for a badge, then lets patching and access hygiene drift, will re-fail the same controls next year and stall the first time an enterprise security team asks a hard question. A firm that uses Cyber Essentials to establish real operational discipline moves smoothly toward ISO 27001 readiness or SOC 2 readiness when the market demands it.
How We Help
We work with UK and international SaaS companies on exactly this progression: getting Cyber Essentials and Cyber Essentials Plus right, then building toward the frameworks that larger buyers require. Our engagements are led by senior practitioners, not junior box-tickers, and we focus on making the controls genuinely work so they survive real scrutiny. If you want the certification to be the start of a defensible security posture rather than a wall decoration, we can help with a security audit, ongoing security leadership through our virtual CISO service, or independent penetration testing to validate that your controls hold. To scope your situation, get in touch. Growing companies without in-house security often start with our cybersecurity services for small business.
Frequently Asked Questions
Is Cyber Essentials mandatory for UK SaaS companies?
It is not universally mandatory, but it is frequently required. Many UK government contracts require it as a minimum, and a growing number of enterprise buyers use it as a due-diligence filter. Whether you strictly need it depends on your customers, but for companies selling into the public sector or regulated industries it is effectively a baseline expectation.
What is the difference between Cyber Essentials and Cyber Essentials Plus?
Cyber Essentials is a self-assessment verified by a certification body. Cyber Essentials Plus applies the same control requirements but adds an independent, hands-on technical audit including vulnerability scanning of a sample of your systems. Plus carries much more weight with serious buyers because the controls are independently verified rather than self-declared.
Are cloud services in scope for Cyber Essentials?
Yes. Current versions of the scheme include cloud services that your organisation administers, alongside end-user devices and servers. This is one of the most common scoping mistakes for SaaS companies, who sometimes assume their cloud-hosted environment is out of scope when it is not.
How long does certification take and how long is it valid?
For an organisation with reasonable controls already in place, basic Cyber Essentials can be achieved in a matter of weeks, while Cyber Essentials Plus takes longer because the controls must genuinely pass a technical audit. Both certifications are valid for twelve months and must be renewed annually.
Can we self-certify instead of hiring a consultant?
Yes, many small companies self-certify successfully, particularly when their estate is small and their controls are already sound. A consultant becomes worthwhile when your environment is complex or cloud-heavy, when scoping is unclear, when you are pursuing Plus and want to pass first time, or when you want certification to feed into a broader security programme.
Does Cyber Essentials replace ISO 27001 or SOC 2?
No. Cyber Essentials is a baseline of technical controls, not a management-system framework. Enterprise and regulated buyers typically expect ISO 27001 or SOC 2 in addition. The discipline Cyber Essentials builds around scope, patching, and access control is a solid foundation for those larger frameworks, but it does not substitute for them.

Alexander Sverdlov
Founder of Atlant Security. Author of 2 information security books, cybersecurity speaker at the largest cybersecurity conferences in Asia and a United Nations conference panelist. Former Microsoft security consulting team member, external cybersecurity consultant at the Emirates Nuclear Energy Corporation.